---
id: CVE-2026-19693
title: >-
  extract-zip: extract-zip: Arbitrary file write via symlink in archive
  (CVE-2026-19693)
summary: >-
  A flaw was found in extract-zip. This vulnerability allows a remote attacker
  to perform an arbitrary file write outside the intended destination directory.
  By crafting a malicious zip archive containing a symbolic link (symlink) and a
  regu…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'
cvssSource: vendor
cwe:
  - CWE-59
  - CWE-22
vendor: Red Hat
product: Red Hat Enterprise Linux 8
affected:
  - node_healthcheck_operator
  - openshift_pipelines
  - build_of_podman_desktop
  - ceph_storage 4
  - enterprise_linux 8
  - enterprise_linux 9
  - enterprise_linux_ai_rhel_ai 3
  - fuse 7
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openshift_gitops
published: '2026-08-17'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T17:08:06+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19693.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19693.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-19693'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2517432'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-19693'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19693'
  - url: 'https://github.com/max-mapper/extract-zip'
  - url: 'https://www.npmjs.com/package/extract-zip'
  - url: 'https://github.com/max-mapper/extract-zip/pull/160'
  - url: 'https://github.com/advisories/GHSA-7pqw-9j4j-h8q3'
tags:
  - csaf
  - vex
  - red-hat
  - nvd
  - ghsa
  - npm
epss: 0.0028
epssPercentile: 0.18184
aliases:
  - GHSA-7pqw-9j4j-h8q3
ecosystem: npm
ingestedAt: '2026-09-08T21:11:12.322Z'
---

## Overview

A flaw was found in extract-zip. This vulnerability allows a remote attacker to perform an arbitrary file write outside the intended destination directory. By crafting a malicious zip archive containing a symbolic link (symlink) and a regular file with the same name, the attacker can bypass security checks. The extract-zip utility incorrectly validates only the parent directory, enabling the attacker to write files to arbitrary locations on the system.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Node HealthCheck Operator, OpenShift Pipelines, Red Hat Build of Podman Desktop, Red Hat Ceph Storage 4, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · no fix planned: Red Hat Build of Podman Desktop, Red Hat Fuse 7, Node HealthCheck Operator, OpenShift Pipelines, … · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19693.json)

**extract-zip: extract-zip: Arbitrary file write via symlink in archive** — rated Important by Red Hat. Released 2026-08-17, updated 2026-09-09.

Affected:

- Node HealthCheck Operator
- OpenShift Pipelines
- Red Hat Build of Podman Desktop
- Red Hat Ceph Storage 4
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat Fuse 7
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift GitOps

No fix planned:

- Red Hat Build of Podman Desktop
- Red Hat Fuse 7
- Node HealthCheck Operator
- OpenShift Pipelines
- Red Hat Ceph Storage 4
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift GitOps

Not affected:

- Multicluster Engine for Kubernetes
- OpenShift Service Mesh 3
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat AMQ Broker 7
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Hardened Images
- Red Hat OpenShift Container Platform 4

## Remediation

Will not fix

## Package advisory (CVE-2026-19693)

Affected packages:

- `extract-zip <= 2.0.1`

Source: https://github.com/advisories/GHSA-7pqw-9j4j-h8q3
